Courseiva
mediumMultiple ChoiceObjective-mapped

350-701 Practice Question: A large enterprise is migrating legacy…

A large enterprise is migrating legacy applications to AWS. The security team requires that all data in transit between the applications and the on-premises data center be encrypted and inspected for threats. They have deployed a Cisco Firepower NGFW on-premises and are using Amazon VPC with a VPN connection. The team is concerned about east-west traffic within the VPC also being inspected. They consider deploying Cisco Secure Firewall in the cloud (cFMC). However, budget constraints limit the number of virtual firewalls. Which design best meets the requirements while optimizing cost?

⚠ Common exam trap

Cisco often tests the concept that a single virtual firewall in a transit VPC can inspect east-west traffic cost-effectively, and the trap here is that candidates mistakenly think AWS Network Firewall (Option C) can replace Cisco Secure Firewall for unified threat inspection across hybrid environments, but it lacks the deep integration with on-premises Firepower and advanced threat detection features required by the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy a single Cisco Secure Firewall virtual instance in a transit VPC and route all inter-VPC traffic through it.

Deploying a single Cisco Secure Firewall virtual instance in a transit VPC allows centralized inspection of all inter-VPC (east-west) traffic while minimizing costs. By routing traffic through the transit VPC, you avoid the expense of deploying a firewall in every VPC, and the on-premises Firepower NGFW handles north-south traffic (VPN and internet-bound). This design meets the encryption and threat inspection requirements for both east-west and north-south traffic within the budget constraint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Inspect all traffic at the on-premises Firepower by routing all cloud traffic through a VPN.

    Why it's wrong here

    Incorrect: This does not inspect east-west traffic that stays within AWS.

  • Deploy a Cisco Secure Firewall virtual instance in each VPC.

    Why it's wrong here

    Incorrect: Increases cost significantly.

  • Use AWS Network Firewall for east-west inspection and keep Firepower on-premises for north-south.

    Why it's wrong here

    Incorrect: AWS Network Firewall may not meet all inspection requirements and adds complexity.

  • Deploy a single Cisco Secure Firewall virtual instance in a transit VPC and route all inter-VPC traffic through it.

    Why this is correct

    Correct: Central inspection reduces cost while covering east-west.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.